Uploaded image for project: 'Red Hat OpenStack Services on OpenShift'
  1. Red Hat OpenStack Services on OpenShift
  2. OSPRH-3167

novnc allowing open direction which could potentially be used for phishing

XMLWordPrintable

    • 2
    • False
    • False
    • openstack-nova-27.1.1-18.0.20230930093334.a869ab1.el9ost
    • None
    • Undefined
    • Moderate

      Copied from the upstream bug [1]:

      "This bug report is related to Security.

      Currently novnc is allowing open direction, which could potentially be used for phishing attempts

      To test.
      https://<sites' vnc domain>//example.com/%2F..
      include .. at the end

      For example:
      http://vncproxy.my.domain.com//example.com/%2F..

      It will redirect to example.com. You can replace example.com with some legitimate domain or spoofed domain.

      The description of the risk is
      By modifying untrusted URL input to a malicious site, an attacker may successfully launch a phishing scam and steal user credentials.
      Because the server name in the modified link is identical to the original site, phishing attempts may have a more trustworthy appearance."

      [1] https://bugs.launchpad.net/nova/+bug/1927677

              mwitt@redhat.com melanie witt
              jira-bugzilla-migration RH Bugzilla Integration
              rhos-workloads-compute
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: